Insider Attacks Against Non-Financial Organizations
Abstract
Recently, several public and private sectors, such as governments, companies, and universities, use Information and Communication Technologies (ICT) to transform paper-based systems into electronic services. E-service systems may be exposed to various electronic attacks such as identity theft and phishing attacks. Attacks are classified into insider and outsider attacks. Several studies show that insider attackers are more dangerous than outsider attackers. Non-financial organizations such as civil registers and universities have sensitive and valuable information that may be exposed to insider attacks. In this paper, we select the Student Information System at Sebha University-Faculty of Science as a case study in order to investigate the susceptibility of end users to insider attacks using social engineering and phishing techniques. We performed two steps to achieve our goal. Firstly, we develop a conceptual model of an attacker instead of performing a real attack. Secondly, we made a survey questionnaire in order to assess to which extent end users are susceptible to insider attack based on the conceptual model.
The analysis of end users' responses using statistical tests shows that a large number of end users at the target organization are susceptible to insider attacks easily. Weak computer skills and lack of information security culture are the main factors enabling insider attacks to successfully attack the organization. Therefore, Sebha University-Faculty of Science needs to improve the skills as well as security culture of their end users to protect end users' records as well as resources. Training end users to create their emails and their online accounts by themselves is one possible way to improve skills. Awareness of end users with risks of electronic crimes by seminars is another way to improve security culture.
Full text article
References
[1]-A. Scupola, Cases on Managing E-services. IGI Global, 2008.
[2]-J. Holgersson and F. Karlsson, “Public e-service development: Understanding citizens’ conditions for participation,” Government Information Quarterly, vol. 31, no. 3, pp. 396–410, 2014.
[3]-F. Havasi, F. A. Meshkany, and R. Hashemi, “E-banking: Status, implementation, challenges, opportunities,” IOSR Journal of Humanities and Social Science, vol. 12, no. 6, pp. 40–48, 2013.
[4]-J. Liu, X. Liu, B. Zheng, and J. Tang, “Design and implementation of code security inspection system based on SVN,” in Computer Science and Service System (CSSS), 2011 International Conference on, 2011, pp. 330–333.
[5]-W. Maes, T. Heyman, L. Desmet, and W. Joosen, “Browser protection against cross-site request forgery,” in Proceedings of the first ACM workshop on Secure execution of untrusted code, 2009, pp. 3–10.
[6]-T. Alexenko, M. Jenne, S. D. Roy, and W. Zeng, “Cross-site request forgery: attack and defense,” in Consumer Communications and Networking Conference (CCNC), 2010 7th IEEE, 2010, pp. 1–2.
[7]-O. Delgado, A. Fuster-Sabater, and J. M. Sierra, “Analysis of new threats to online banking authentication schemes,” in X Spanish Meeting on Cryptology and Information Security-RECSI, 2008, pp. 337–344.
[8]-F. Mouton, L. Leenen, M. M. Malan, and H. S. Venter, “Towards an ontological model defining the social engineering domain,” in IFIP International Conference on Human Choice and Computers, 2014, pp. 266–279.
[9]-D. M. Lynch, “Securing Against Insider Attacks.,” Information Systems Security, vol. 15, no. 5, pp. 39–47, 2006.
[10]-J. Hunker and C. W. Probst, “Insiders and Insider Threats-An Overview of Definitions and Mitigation Techniques.,” JoWUA, vol. 2, no. 1, pp. 4–27, 2011.
[11]-K. Krombholz, H. Hobel, M. Huber, and E. Weippl, “Social engineering attacks on the knowledge worker,” in Proceedings of the 6th International Conference on Security of Information and Networks, 2013, pp. 28–35.
[12]-W. Cornelissen, “Investigatinginsider threats: problems and solutions.” University of Twente, 2009.
[13]-O. Elaswad and C. D. Jensen, “Identity management for e-government Libya as a case study,” in Information Security for South Africa (ISSA), 2016, 2016, pp. 106–113.
Authors

This work is licensed under a Creative Commons Attribution 4.0 International License.
In a brief statement, the rights relate to the publication and distribution of research published in the journal of the University of Sebha where authors who have published their articles in the journal of the university of Sebha should how they can use or distribute their articles. They reserve all their rights to the published works, such as (but not limited to) the following rights:
- Copyright and other property rights related to the article, such as patent rights.
- Research published in the journal of the University of Sebha and used in its future works, including lectures and books, the right to reproduce articles for their own purposes, and the right to self-archive their articles.
- The right to enter a separate article, or for a non-exclusive distribution of their article with an acknowledgment of its initial publication in the journal of Sebha University.
Privacy Statement The names and e-mail addresses entered on the Sabha University Journal site will be used for the aforementioned purposes only and for which they were used.